PT-2024-4291 · Microsoft · Mskssrv.Sys +2
Angelboy
·
Published
2024-06-11
·
Updated
2025-08-30
·
CVE-2024-35250
Angelboy
·
Published
2024-06-11
·
Updated
2025-08-30
·
CVE-2024-35250
7.8
High
Base vector | Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Windows Kernel-Mode Driver (affected versions not specified)
Description:
The issue is related to an untrusted pointer dereference weakness in the Microsoft Kernel Streaming Service (MSKSSRV.SYS), allowing local attackers to gain SYSTEM privileges in low-complexity attacks that don't require user interaction. This vulnerability is being actively exploited to gain SYSTEM privileges on compromised machines. The estimated number of potentially affected devices worldwide is not specified. However, it is mentioned that over 145,000 servers are potentially at risk due to a related vulnerability.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Buffer Overflow
Untrusted Pointer Dereference